Two domain-joined Windows Server 2022 hosts (App1 and App2) are on the same subnet. You must ensure that only SMB traffic between App1 and App2 is encrypted with IPsec; all other traffic between the hosts should be unaffected. What should you configure? Choose two.
Choose an answer
Tap an option to check your answer.
Correct answer: Create a server-to-server Connection Security Rule in transport mode that requires encryption and uses Kerberos for authentication between App1 and App2., Create an inbound Windows Defender Firewall rule on both servers for TCP 445 that allows the connection only if it is secure (IPsec)..
Why this is the answer
To encrypt only SMB traffic between App1 and App2, you need to configure both an IPsec connection security rule and a firewall rule. A server-to-server Connection Security Rule in transport mode ensures that only the data payload (SMB traffic in this case) is encrypted, leaving the IP header intact. Requiring encryption ensures the traffic is always protected, and Kerberos is the appropriate authentication method for domain-joined servers. An inbound Windows Defender Firewall rule for TCP port 445 (SMB) on both servers, configured to allow connections only if they are secure (IPsec), restricts SMB communication to only encrypted traffic, fulfilling the requirement. Incorrect options: Tunnel mode IPsec encrypts the entire IP packet, including the IP header, and is typically used for site-to-site VPNs, not for securing traffic between hosts on the same subnet. Preshared keys are less secure and harder to manage than Kerberos for domain-joined environments. An IPsec exemption for ICMP is not relevant to securing SMB traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed